laravel/framework
Packagist13 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting laravel/frameworkpage 1 of 1
- CVE-2017-14775MEDIUMCVSS 5.9EG 5.9fixed in 5.5.102017-09-28
vulnerable: 5.0.30 ... v5.5.9 (281 versions)
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
- CVE-2017-9303MEDIUMCVSS 6.1EG 6.1fixed in 5.4.222017-05-29
vulnerable: v5.4.0 ... v5.4.9 (22 versions)
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.
- CVE-2018-15133CRITICALCVSS 8.1EG 9.0⚠ KEVfixed in 5.6.302018-08-09
vulnerable: v5.6.0 ... v5.6.9 (30 versions)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Enc…
- CVE-2020-19316HIGHCVSS 8.8EG 8.8fixed in 5.8.172021-12-20
vulnerable: 5.0.30 ... v5.8.9 (410 versions)
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
- CVE-2020-24941HIGHCVSS 7.5EG 7.5fixed in 6.18.35 or 7.24.0, by version range2020-09-04
vulnerable: v7.0.0 ... v7.9.2 (59 versions)
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.
- CVE-2021-21263HIGHCVSS 7.2EG 7.2fixed in 8.22.1, 6.20.11 or 7.30.2, by version range2021-01-19
vulnerable: v7.0.0 ... v7.9.2 (75 versions)
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/database package which is used by Laravel. If a request is craf…
- CVE-2021-43808MEDIUMCVSS 5.3EG 5.3fixed in 6.20.42, 7.30.6 or 8.75.0, by version range2021-12-08
vulnerable: v8.0.0 ... v8.9.0 (112 versions)
Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element may be clicked and the user tak…
- CVE-2024-13918HIGHCVSS 8.0EG 8.0fixed in 11.36.02025-03-10
vulnerable: v11.10.0 ... v11.9.2 (45 versions)
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
- CVE-2024-13919HIGHCVSS 8.0EG 8.0fixed in 11.36.02025-03-10
vulnerable: v11.10.0 ... v11.9.2 (45 versions)
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
- CVE-2024-52301HIGHCVSS 7.5EG 7.9fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23 or 11.31.0, by version range2024-11-12
vulnerable: v11.0.0 ... v11.9.2 (54 versions)
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the re…
- CVE-2025-27515CRITICALCVSS 9.8EG 9.8fixed in 12.1.1, 11.44.1 or 10.48.29, by version range2025-03-05
vulnerable: 5.0.30 ... v9.9.0 (1018 versions)
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.4…
- CVE-2026-102279LOWCVSS 3.1EG 3.1fixed in 12.69.0 or 13.30.0, by version range2026-09-28
vulnerable: v13.0.0 ... v13.9.0 (37 versions)
Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML true, enabling DOM-based cross-site scri…
- CVE-2026-48019HIGHCVSS 8.9EG 8.9fixed in 13.10.0 or 12.60.0, by version range2026-09-04
vulnerable: 10.50.2 ... v9.9.0 (1237 versions)
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may al…
Check whether laravel/framework is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for laravel/framework CVEs against the assets you own.
Book a Demo →